AI progress — 9 October 2026
Anthropic launched OSS Scanner, a free service that scans open-source projects for security vulnerabilities. Maintainers who lack a security budget can now get a scan at no cost. Elsewhere, CNBC reports OpenAI annualised revenue is $20B below what was previously signalled, and three fired OpenAI safety researchers published an open letter disputing the misconduct claims against them.
New models and papers
- Step 5 Preview from StepFun — a 1M-context mixture-of-experts model that has appeared on OpenRouter. Why it matters: it can be called through an existing router today, so long-context workloads can be tested without new infrastructure. No benchmarks appear in the source.
- TokenRouter: Efficient Serving System for Token-Level LLM Routing — a serving system for routing individual tokens between models rather than whole queries or sessions. Why it matters: the authors say prior algorithmic work shows token-level routing gains in cost and quality, and this paper targets the serving side that makes it practical.
- What Did the Agent Actually Do? Evidence-Grounded Oversight for Long-Horizon Agents — a study of monitors that flag consequential agent decisions and locate the evidence a user needs to check them. Why it matters: long-running agents produce more activity than a person can review, so deciding what to verify is the bottleneck.
New tools and software
- Claude Code v2.1.295 — adds
onFailure: "block"for command and HTTP hooks. Why it matters: a hook that fails to start, times out or exits unexpectedly now blocks the action instead of letting it through, which matters for anyone using hooks as guardrails. - Codex rust-v0.162.0 — adds tools to create and list managed Git worktrees from trusted local projects, when the worktrees feature is enabled. Why it matters: agents can work on parallel branches in isolated checkouts.
- Ollama v0.40.2 — upgrades models downloaded by earlier versions in the background on first run, keeping the original as a backup. Why it matters: expect extra disk use until the backups are removed; the release notes include a command to clear them now.
Overall digest
- Anthropic launches free AI security scans for open-source projects — a service called OSS Scanner that helps open-source projects find vulnerabilities. Why it matters: open-source maintainers get a no-cost option for security review.
- OpenAI annualised revenues $20B less than previously signalled — CNBC reports a lower annualised revenue figure than earlier signals suggested. Why it matters: the headline links it to Nvidia, Oracle and CoreWeave; read the article for the detail, as the summary here is limited to the headline.
- Fired OpenAI safety researchers dispute misconduct claims — three fired researchers deny mishandling sensitive information and say in an open letter that the dismissals chill safety culture at the company. Why it matters: these are the researchers’ claims, not established findings; OpenAI’s side is not in the summary.
Get the AI digest by email
One email per weekday morning: new models and papers, new tools, and the overall picture. No ads, unsubscribe in one click. See the privacy policy.